CVE Vulnerabilities

CVE-2014-5139

Published: Aug 13, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
1.9 MODERATE
AV:L/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl1.0.1 (including)1.0.1 (including)
OpensslOpenssl1.0.1-beta1 (including)1.0.1-beta1 (including)
OpensslOpenssl1.0.1-beta2 (including)1.0.1-beta2 (including)
OpensslOpenssl1.0.1-beta3 (including)1.0.1-beta3 (including)
OpensslOpenssl1.0.1a (including)1.0.1a (including)
OpensslOpenssl1.0.1b (including)1.0.1b (including)
OpensslOpenssl1.0.1c (including)1.0.1c (including)
OpensslOpenssl1.0.1d (including)1.0.1d (including)
OpensslOpenssl1.0.1e (including)1.0.1e (including)
OpensslOpenssl1.0.1f (including)1.0.1f (including)
OpensslOpenssl1.0.1g (including)1.0.1g (including)
OpensslOpenssl1.0.1h (including)1.0.1h (including)
OpensslUbuntudevel*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuupstream*

References